Best way to find out what happened in a shared mailbox through the audit logs?

%3CLINGO-SUB%20id%3D%22lingo-sub-359727%22%20slang%3D%22en-US%22%3EBest%20way%20to%20find%20out%20what%20happened%20in%20a%20shared%20mailbox%20through%20the%20audit%20logs%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-359727%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20everyone%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20case%20where%20someone%20claims%20several%20mails%20between%20Jan%201st%20and%20Febr%2027th%20were%20not%20received%20into%20a%20specific%20shared%20mailbox.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20checked%20message%20trace%20and%20there%20I%20can%20find%20all%20of%20them%20with%20a%20state%20of%20'delivered%20to%20Inbox'.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20I%20know%20that%20doesn't%20automatically%20mean%20'well%20someone%20must%20have%20deleted%20them'%20so%20I%20need%20to%20find%20out%20what%20exactly%20happened%20to%20those%20mails%20after%20getting%20to%20the%20Inbox.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20fact%20that%20it's%20a%20shared%20mailbox%20(with%208%20people%20having%20access)%20means%20I%20will%20have%20to%20look%20at%20audit%20logs%20of%20all%208%20people%20but%20for%20such%20a%20long%20period%20of%20time%2C%20I%20fear%20if%20I%20just%20look%20for%20deleted%2Fpurged%20items%20for%20all%208%20users%2C%20I%20am%20going%20to%20get%20a%20huge%20file%20which%20will%20be%20very%20difficult%20to%20sifle%20through.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThe%20subject%20of%20the%20missing%20mails%20is%20always%20the%20same%20but%20haven't%20found%20an%20'ItemSubject'%20variable%20I%20can%20use%20on%20EXO....%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20tips%20on%20how%20to%20best%20tackle%20this%20and%20next%20steps%20if%20audit%20log%20does%20not%20provide%20answers%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-359727%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-360728%22%20slang%3D%22en-US%22%3ERe%3A%20Best%20way%20to%20find%20out%20what%20happened%20in%20a%20shared%20mailbox%20through%20the%20audit%20logs%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-360728%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Vasil.%20Mailbox%20search%20did%20the%20trick.%20They%20were%20effectively%20deleted%20but%20of%20course%2C%20nobody%20actually%20deleted%20them%20when%20you%20ask%20the%20people%20who%20have%20access%20to%20the%20shared%20mailbox%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-359802%22%20slang%3D%22en-US%22%3ERe%3A%20Best%20way%20to%20find%20out%20what%20happened%20in%20a%20shared%20mailbox%20through%20the%20audit%20logs%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-359802%22%20slang%3D%22en-US%22%3E%3CP%3EAuditing%20isn't%20enabled%20by%20default%20for%20shared%20mailboxes%2C%20so%20you%20might%20not%20get%20any%20information%20from%20there.%20I'd%20suggest%20doing%20a%20mailbox%20search%20or%20eDiscovery%20content%20search%20for%20the%20missing%20messages%20(both%20of%20these%20accept%20a%20subject%20query).%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Hi everyone

 

I have a case where someone claims several mails between Jan 1st and Febr 27th were not received into a specific shared mailbox.

 

I checked message trace and there I can find all of them with a state of 'delivered to Inbox'. 

 

Now I know that doesn't automatically mean 'well someone must have deleted them' so I need to find out what exactly happened to those mails after getting to the Inbox.

 

The fact that it's a shared mailbox (with 8 people having access) means I will have to look at audit logs of all 8 people but for such a long period of time, I fear if I just look for deleted/purged items for all 8 users, I am going to get a huge file which will be very difficult to sifle through.

 

The subject of the missing mails is always the same but haven't found an 'ItemSubject' variable I can use on EXO....

 

Any tips on how to best tackle this and next steps if audit log does not provide answers?

2 Replies
Highlighted

Auditing isn't enabled by default for shared mailboxes, so you might not get any information from there. I'd suggest doing a mailbox search or eDiscovery content search for the missing messages (both of these accept a subject query).

Highlighted

Thanks Vasil. Mailbox search did the trick. They were effectively deleted but of course, nobody actually deleted them when you ask the people who have access to the shared mailbox :)